A tamper-evident record for AI decisions
Boruna runs AI and LLM workflows deterministically, under an explicit capability
policy, and seals every run into a hash-chained evidence bundle. Anyone can verify the bundle
offline, and any change to it is detected.
Install
Quickstart
Every run is evidence
Each completed step with the hash of its output, every approval or rejection and every
confidence-gate decision goes into a hash-chained audit log inside an evidence bundle. boruna evidence verify
recomputes every hash and reports any change.
How bundles are verified →
People decide where it matters
Approval gates pause a workflow until someone runs boruna workflow approve.
A calibrated confidence gate lets an answer skip review only when calibration data shows a
wrong answer would get through at most a set share of the time.
Approval and confidence gates →
Same input, same output
Workflow steps are written in .ax and run on a VM with no ambient randomness,
clock or I/O. Network, LLM and file access must be declared and allowed by policy. A program run
with boruna run --record records every such call and its result, so the run can be
replayed and checked.
How replay works →
Reports for EU AI Act, NIST AI RMF and ISO/IEC 42001
boruna evidence report --framework eu-ai-act (or nist,
iso42001) verifies a bundle and maps what it contains to the obligations each part
helps meet. It is a technical mapping for your auditor, not a certificate of compliance.
Compliance workflow templates →
Run a workflow, then verify it
Real output from boruna 3.5.0, captured when this page was built.
$ boruna workflow run examples/workflows/confidence_gated_review --policy allow-all --record
data_dir: runs
workflow 'confidence-gated-review' run: Completed
run_id: 9fc7168a51f1f54d
duration: 3ms
step 'publish': Completed (0ms)
step 'review': Completed (0ms)
step 'score': Completed (0ms)
evidence bundle: runs/evidence/9fc7168a51f1f54d
bundle_hash: a8a3f9f49f2fc19c1835dab2124e12425d95e8043698a1e71e7a86d8afbbe53b
audit_log_hash: cc92dd1f10a08b5a405f01cf258056466db50eed1ac6e350d4ddabef8468856f
files: 6
$ boruna evidence verify runs/evidence/9fc7168a51f1f54d
evidence bundle is VALID
Install
Linux and macOS:
curl -fsSL https://raw.githubusercontent.com/escapeboy/boruna/master/install.sh | sh
Windows (PowerShell):
irm https://raw.githubusercontent.com/escapeboy/boruna/master/install.ps1 | iex
Both scripts check the download against the release's SHA256SUMS before
installing. Builds for Linux (x86_64, arm64), macOS (Apple Silicon, Intel) and Windows (x64,
Arm), each tested natively in CI. Manual
download and platform table →
For developers and AI agents
- The
.ax language — small,
statically typed and deterministic.
- MCP server — compile, check, run and seal
.ax from Claude Code, Cursor and other agents.
llms.txt and llms-full.txt
— the language and tooling in a form a model can read in one go.
- Limitations — what Boruna does not do, stated plainly.